| 2018-09-19 | When EL Injection meets Java Deserialization | re4lity | 2671 | |
| 2018-09-19 | Intercepting and Modifying responses with Chrome via the Devtools Protocol | re4lity | 2595 | |
| 2018-09-19 | A Tale of Two Bugs · Our Machinery | re4lity | 1939 | |
| 2018-09-19 | XSS Vulnerabilities in Multiple iFrame Busters Affecting Top Tier Sites | re4lity | 2378 | |
| 2018-09-19 | Peekaboo Critical Vulnerability in NUUO Network Video Recorder | re4lity | 1716 | |
| 2018-09-19 | Cheatsheet - Flask & Jinja2 SSTI | re4lity | 2906 | |
| 2018-09-19 | 碎碎念之Afl-fuzz Docker实践 | re4lity | 2006 | |
| 2018-09-14 | Android平台间谍软件BusyGasper分析 | birk | 10394 | |
| 2018-09-09 | 突破限制—一份安全编写和审计Chrome扩展程序的指南(下) | ginove | 2819 | |
| 2018-09-07 | 突破限制—一份安全编写和审计Chrome扩展程序的指南(上) | ginove | 1775 | |
| 2018-09-06 | 子域名劫持指南 | YSN | 4802 | |
| 2018-09-02 | 利用GIXY发现错误的Nginx配置 | ginove | 6470 | |
| 2018-09-02 | 技术报告:绕过工作流保护机制 - SharePoint远程代码执行 | ginove | 2385 | |